IBM Security Bulletin: InstallShield and InstallAnywhere vulnerabilities affect IBM Security Guardium Data Redaction (CVE-2016-2542)

Flexera InstallShield could allow a local attacker to gain elevated privileges on the system, caused by an untrusted search path. An attacker could exploit this vulnerability using a Trojan horse DLL in the current working directory of a setup-launcher executable file to gain elevated privileges on the system.

CVE(s): CVE-2016-2542

Affected product(s) and affected version(s):

2.5.1

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/28KX6tD
X-Force Database: http://ift.tt/1rhWtyP



from IBM Product Security Incident Response Team http://ift.tt/28KX70F